# Membership System Setup Guide ## Overview This membership system provides: - User registration and authentication - IP-based download limiting (1 free download, unlimited for members) - Paywall for library downloads, contact form, and testimonials - Admin panel for membership approval - Buy Me a Coffee integration ($5 minimum donation) ## Prerequisites 1. Python 3.7+ with pip 2. Flask and other dependencies (see requirements.txt) 3. SMTP server access for email notifications (optional but recommended) ## Installation 1. Install Python dependencies: ```bash cd /root/hydro-sterile pip3 install -r requirements.txt ``` 2. Set environment variables: ```bash export ADMIN_PASSWORD="your-very-secure-password-here" export ADMIN_EMAIL="indiana.holmes8@gmail.com" export JWT_SECRET="$(openssl rand -hex 32)" export MEMBERSHIP_PORT=5001 # Optional: SMTP configuration for email notifications export SMTP_HOST="smtp.gmail.com" export SMTP_PORT=587 export SMTP_USER="your-email@gmail.com" export SMTP_PASS="your-app-password" ``` 3. Create a systemd service or run manually: ```bash python3 /root/hydro-sterile/scripts/membership_api.py ``` ## Configuration ### API Endpoints The membership API runs on port 5001 by default. Update the API_BASE URL in: - `/root/hydro-sterile/static/js/membership.js` (line 4) - `/root/hydro-sterile/layouts/admin/single.html` (line 186) For production, change from `http://10.30.20.243:5001` to your production domain. ### Admin Panel Access the admin panel at `/admin/` on your Hugo site. The admin password is set via the `ADMIN_PASSWORD` environment variable. Use a strong password! ### Database The SQLite database is automatically created at: `/root/hydro-sterile/data/members.db` Backup this file regularly! ## User Flow 1. User visits paywalled page (library, contact, testimonials) 2. Non-members see paywall message directing to membership page 3. User completes Buy Me a Coffee donation ($5 minimum) 4. User signs up with email/password on membership page 5. System sends email notification to admin 6. Admin logs into admin panel and approves/denies membership 7. Approved user receives confirmation email 8. User can now log in and access all paywalled content ## Security Notes - Admin password should be very strong (20+ characters recommended) - JWT_SECRET should be a random string (use `openssl rand -hex 32`) - Never commit ADMIN_PASSWORD or JWT_SECRET to version control - Database file should have restricted permissions (600) - SMTP credentials should use app passwords, not main account password ## Email Configuration For Gmail: 1. Enable 2-factor authentication 2. Generate an app password 3. Use the app password as SMTP_PASS ## Troubleshooting ### API not starting - Check port 5001 is not in use: `netstat -tuln | grep 5001` - Check Python dependencies: `pip3 list | grep -E "flask|bcrypt|jwt"` ### Database errors - Ensure `/root/hydro-sterile/data/` directory exists and is writable - Check file permissions: `chmod 600 /root/hydro-sterile/data/members.db` ### Email not sending - Check SMTP credentials - Verify SMTP_HOST and SMTP_PORT are correct - Check firewall allows outbound SMTP connections - Email sending failures won't break the system, but admin won't get notifications ### Frontend not connecting to API - Check API_BASE URL in membership.js matches your server - Check CORS settings in membership_api.py - Check browser console for errors - Verify API is running: `curl http://localhost:5001/api/health` ## Maintenance - Regularly backup `/root/hydro-sterile/data/members.db` - Monitor API logs for errors - Review pending memberships regularly - Clean up old sessions periodically (optional, sessions expire automatically)